Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)New$46K–$183K

The opportunity

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the…

What you'll do

  • Reverse engineer malware nobody has documented yet. Take apart obfuscated and: packed samples across Windows, macOS, and Linux, and recover how they communicate, configure themselves, and stay hidden.

  • Operate global data systems to identify and mitigate threats. Work through: data from millions of endpoints to surface the activity worth investigating, build the campaign context that tells customers who is targeting them, and push mitigation back out across the fleet.

  • Turn every discovery into a shipped protection, and the tooling that scales: it. Author the signatures that stop what you find, and build the automation and AI-assisted workflows that make the next investigation faster than the last.

  • Build your public research reputation. Publish on Elastic Security Labs,: release tools and detection artifacts to our public GitHub repositories, and present at conferences. We encourage a public persona and the relationships in the research community that come with it.

  • Collaborate across Elastic Security. Your discoveries become the rules and: models that neighboring teams build and ship, and you will work with those teams directly on shared threat intelligence and detection engineering projects.

  • Help lead the team's technical direction. Take point on investigations that: run for months, raise the bar in review, and mentor researchers earlier in their careers.

What they're looking for

  • + years of professional experience reverse engineering malware and: researching adversary tradecraft, static and dynamic, across multiple executable formats (PE, ELF, Mach-O) and architectures (x86-64, ARM), including obfuscated and packed code that defeats automated tooling.
  • Python development experience for research tooling and automation, plus the: ability to read C and C++. Malware arrives in Rust, Go, and NodeJS too, so you are willing to learn a new runtime when a sample demands it.
  • YARA authorship and hunting at scale. You write signatures that hold up: against the next variant, and you can find a weak signal in a very large telemetry dataset.
  • Working knowledge of the fundamentals: Windows and Linux internals, network protocols including HTTP and TLS, and enough applied cryptography to recognize what is protecting a configuration blob.